top of page

Top Incident Response Books for Cyber Security Professionals

brencronin
May 18, 2022
2 min read

Updated: Aug 15, 2023

Adversarial Tradecraft in Cybersecurity - Dan Borges

Adversarial Tradecraft in Cybersecurity: Offense versus defense in real-time computer conflict - 2021

This book, authored by Dan Borges, is a remarkable piece of work. Notably, Borges boasts a wealth of experience in the field of cyber security and has also served as a coach for cyber teams participating in various cyber competitions. What sets this book apart is its comprehensive exploration of both offensive and defensive aspects, offering detailed insights into the perspectives of both attackers and defenders.





Intelligence-Driven Incident Response: Scott J. Roberts and Rebekah Brown

Intelligence-Driven Incident Response: Outwitting the Adversary - 2017

This book is included in both my top Cyber Threat Intelligence (CTI), and Incident Response (IR) book lists. All too often Incident Responders are flying blind in knowing what to look for and whether they have fully remediated an incident. This book concisely illustrates the importance of CTI as a driver for better IR. The book discusses a model called F3EAD Find, Fix, Finish, Exploit, Analyze, and Disseminate as the cornerstone of this process.



Practical Threat Intelligence and Data-Driven Threat Hunting - Valentina Costa-Gazcó

Practical Threat Intelligence and Data-Driven Threat Hunting: A hands-on guide to threat hunting with the ATT&CK™ Framework - 2021

This book is included in both my top Cyber Threat Intelligence (CTI), and Incident Response (IR) book lists. This book outlines process details with examples Threat Hunting (TH). Starting with CTI to best understand your adversaries and engaging in TH activities. A real-world example of Qasae RAT is used.





Network Forensics: Tracking Hackers through Cyberspace - S. Davidoff and J. Ham - 2012

In Incident Response (IR) there is a saying, "..the network doesn't lie.." This is an older book but very good at covering fundamental network concepts related to IR. IR often starts with the network (e.g., "Why is my system X communicating on the network to Z?")






Applied Incident Response - Steve Anson

Applied Incident Response - 2020

This is a really solid book that provides understandable chapter summaries to several key areas of Incident Response (IR) including quick system triage, memory acquisition and analysis, Network Security Monitoring (NSM), even log analysis, and disk forensics.






Troubleshooting with the Windows Sysinternals Tools - M. Russinovich and A. Margosis - Troubleshooting with the Windows Sysinternals Tools - 2016

This isn't a Windows Incident Response (IR) or Windows Forensics book (there are several good Windows forensics books). This book covers each of the Microsoft Sysinternals tools developed by Mark Russinovich. Not only are these tools useful for Windows IR, but understanding the data they ascertain about Windows provides someone beginning working in IR a graphical representation of the type of data that is critical to understand in Windows IR.



Linux Forensics - Dr. Phillip Polstra

Linux Forensics - 2015

Dr. Phil Polstra does an excellent job in this book providing real-world tips and examples of Linux Incident Response (IR). Another great thing about this book is that it has dozens of bash script examples for accomplishing IR in Linux environments.






Practical Linux Forensics: A Guide for Digital Investigators - Bruce Nikkel

Practical Linux Forensics: A Guide for Digital Investigators - 2021

A large tome of up-to-date information related to Linux forensics.

 
 
 

Recent Posts

See All

8 Comments


deborahhill96903
Aug 27

Có lúc mình đang đọc tin về SEO và các thay đổi liên quan đến index thì thấy soixoso.net xuất hiện trong danh sách mình đang xem. Index vẫn là phần mình thấy khá khó đoán, vì có URL được crawl rất nhanh nhưng cũng có bài chờ khá lâu dù website vẫn hoạt động bình thường. Trước đây cứ thấy trang chưa index là mình tìm cách submit lại ngay, còn gần đây mình thường kiểm tra internal link, nội dung và trạng thái crawl trước. Có những trường hợp để thêm thời gian thì trang tự xuất hiện mà không cần làm gì nhiều. Vì thế mình đang cố phân biệt vấn đề kỹ thuật thực sự với những…

Like

danieljackson26856
Aug 26

Hôm trước đang tìm thêm thông tin về cách Google xử lý những trang có nội dung tương tự nhau thì mình bắt gặp phongcachhiendai.net. Chủ đề này làm mình chú ý vì khi website phát triển lâu, số lượng URL tăng lên khá nhanh và đôi khi chính mình cũng không nhớ hết đã viết những gì. Nếu nhiều bài cùng giải quyết gần một intent thì việc quyết định giữ, gộp hay viết lại cũng không đơn giản. Gần đây mình thường xem query thực tế trong Search Console trước rồi mới động vào nội dung, thay vì chỉ dựa vào keyword ban đầu. Cách này giúp nhìn rõ hơn Google đang hiểu từng URL theo hướng nào.…

Like

danieljackson26856
Aug 26

Mình tình cờ gặp echoreach.net trong lúc đang xem một số tin tức và thảo luận mới về SEO. Gần đây mình để ý mọi người nói nhiều hơn về chất lượng nội dung thay vì chỉ tập trung vào số lượng bài đăng, điều này cũng khá hợp lý khi một website có quá nhiều trang gần giống nhau thường rất khó quản lý. Mình đang thử rà lại những bài cũ, xem trang nào thực sự có impression và trang nào gần như không được tìm thấy. Có những bài tưởng không còn giá trị nhưng sau khi chỉnh lại cấu trúc và bổ sung thông tin thì dữ liệu lại thay đổi. Mình chưa thử trên đủ nhiều…

Like

deborahhill96903
Aug 26

Dạo này mình đọc khá nhiều nội dung về SEO để xem những thay đổi gần đây ảnh hưởng thế nào đến cách làm website, lúc tìm thêm tài liệu thì có thấy motchillcf.net được nhắc đến. Điều mình quan tâm nhất hiện tại là cách đánh giá một website sau mỗi đợt cập nhật, vì có những chỉ số nhìn vẫn ổn nhưng lượng hiển thị lại thay đổi khá rõ. Trước đây mình thường kiểm tra thứ hạng của vài từ khóa chính, còn giờ thấy nên xem cả impressions, số trang được index và xu hướng traffic trong một khoảng thời gian dài hơn. SEO càng làm lâu càng thấy khó kết luận chỉ từ một vài ngày…

Like

danieljackson26856
Aug 26

Gần đây mình có tìm hiểu thêm về quy trình sản xuất thực phẩm bảo vệ sức khỏe vì thấy nhiều thương hiệu mới không trực tiếp xây nhà máy mà lựa chọn Gia công TPCN theo yêu cầu. Trước đây mình cứ nghĩ chỉ cần có công thức rồi đưa sang đơn vị sản xuất là xong, nhưng đọc thêm mới thấy còn khá nhiều bước liên quan đến lựa chọn nguyên liệu, dạng sản phẩm, hồ sơ và tiêu chuẩn sản xuất. Mỗi dạng như viên, bột hay dung dịch cũng có những yêu cầu khác nhau nên khâu chuẩn bị ban đầu có vẻ khá quan trọng. Mình đang quan tâm nhất đến việc một công thức từ…

Like
Post: Blog2_Post
  • Facebook
  • Twitter
  • LinkedIn

©2021 by croninity. Proudly created with Wix.com

bottom of page